ln-24-architecture-decision-recorder

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions require the agent to ingest and synthesize potentially untrusted data from the repository and external stakeholders into Architecture Decision Records (ADRs).
  • Ingestion points: The skill reads repository instructions, Git state, existing decision conventions, and stakeholder statements (SKILL.md, Checklist items 1 and 2).
  • Boundary markers: The instructions do not define delimiters or explicit "ignore embedded instructions" warnings for the external data being processed.
  • Capability inventory: The skill is authorized to perform repository searches, direct document reads, and file system writes/patches to create ADR files in the docs/architecture/decisions/ directory (SKILL.md, Tool Routing).
  • Sanitization: There are no provisions for sanitizing, escaping, or filtering data extracted from external sources before it is interpolated into the generated documentation.
  • [NO_CODE]: The skill consists exclusively of markdown instructions (SKILL.md) and does not include any accompanying scripts, binaries, or automated configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 03:19 PM
Security Audit — agent-trust-hub — ln-24-architecture-decision-recorder